pcfixkit_setup.exe

PCFixKit

SumYum Info Tech Co.,Ltd.

The executable pcfixkit_setup.exe, “PCFixKit Setup ” has been detected as malware by 8 anti-virus scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
www.PCFixKit.com   (signed by SumYum Info Tech Co.,Ltd.)

Product:
PCFixKit

Description:
PCFixKit Setup

Version:
2.1

MD5:
03d57853e069b02b0067c6f43d6755f5

SHA-1:
52664bd924dc6e7133c2fa218bc55b53389ae73a

SHA-256:
3f95338c81f3b8cb7af4feae03253294f09dbb668a06e97c5d07ef2734b3fc1f

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
11/16/2024 10:47:19 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Zbot-THZ [Trj]
160326-0

Dr.Web
Trojan.Inject1.36963
9.0.1.05190

ESET NOD32
Win32/TrojanDropper.Agent.PYF trojan
8.0.319.0

F-Secure
Variant.Midie.6956
5.15.96

Kaspersky
Backdoor.Win32.Androm
15.0.0.562

McAfee
Trojan.PWSZbot-FIB!03D57853E069
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.219.596.0

Norman
Gen:Variant.Midie.6956
02.04.2016 17:35:19

File size:
3.4 MB (3,549,674 bytes)

Product version:
2.1

Copyright:
Copyright 2015 www.PCFixKit.com

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\pcfixkit_setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/12/2014 5:30:00 AM

Valid to:
12/13/2015 5:29:59 AM

Subject:
CN="SumYum Info Tech Co.,Ltd.", O="SumYum Info Tech Co.,Ltd.", STREET="Nanning Ming Xiu Road, No. 122 City Brist", L=Nanning, S=Guangxi, PostalCode=530000, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DA8A70137917E6F0EFF0A7877F81AE96

File PE Metadata
Compilation timestamp:
8/29/2012 11:52:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:G6e0N5VkBUAVuAn+uyGUbPluSFJspDLOMgdF:G6BVkBUAVr+LGO1IDLwP

Entry address:
0x169F

Entry point:
55, 8B, EC, 6A, FF, 68, F8, 20, 40, 00, 68, 50, 18, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, 5F, 57, FF, 15, D4, 20, 40, 00, 59, 83, 0D, B0, 30, 40, 00, FF, 83, 0D, B4, 30, 40, 00, FF, FF, 15, D0, 20, 40, 00, 8B, 0D, AC, 30, 40, 00, 89, 08, FF, 15, CC, 20, 40, 00, 8B, 0D, A8, 30, 40, 00, 89, 08, A1, C8, 20, 40, 00, 8B, 00, A3, B8, 30, 40, 00, E8, 35, 01, 00, 00, 39, 1D, 90, 30, 40, 00, 75, 0C, 68, 42, 18, 40, 00, FF, 15...
 
[+]

Entropy:
7.8974

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
2.5 KB (2,560 bytes)

Remove pcfixkit_setup.exe - Powered by Reason Core Security